#ColdcardAttackOngoing
Coldcard wallet attack surpasses $116 million as firmware vulnerability continues to impact users
A major security incident continues to unfold across the Bitcoin ecosystem as the ongoing Coldcard hardware wallet attack grows in scale. What initially appeared to be a targeted exploit has developed into one of the largest self-custody security events in Bitcoin's history, with on-chain investigations showing losses continuing to increase through early August.
The incident serves as a powerful reminder that even trusted security products require continuous monitoring, timely updates, and strong operational security practices.
How the vulnerability was exploited
According to research from Galaxy Research, the attack is linked to a firmware vulnerability affecting certain Coldcard devices dating back to March 2021.
The flaw weakened the randomness used during seed phrase generation. Since a wallet's seed phrase is responsible for creating its private keys, reduced randomness makes those keys significantly easier to predict. An attacker can potentially reconstruct affected wallets offline without needing physical access to the device itself.
The first attack wave demonstrated how serious the issue had become, compromising 1,196 wallet addresses within just 41 minutes and draining approximately 1,082 BTC, valued at around $70 million at that time.
Losses continue to rise
Subsequent attack waves expanded the damage considerably.
By August 3, estimated losses had climbed to approximately 1,367 BTC, worth nearly $89 million. Later estimates reported by Forbes placed total losses at more than $116 million, with over 5,200 wallet addresses believed to have been affected.
One widely reported incident involved a single user losing approximately C$1.6 million, despite following commonly recommended hardware wallet security practices.
Galaxy Research has also reported roughly 600 blockchain addresses believed to be associated with the attackers to federal investigators and cybersecurity organizations to support the ongoing investigation.
Manufacturers respond with security updates
The vulnerability has also been confirmed by Block's Bitcoin Engineering and Security team, which attributed the issue to a coding error affecting specific firmware versions.
In response, Coinkite has released updated firmware designed to prevent newly created wallets from being affected going forward. Company CEO Rodolfo Novak has encouraged users to transfer their assets immediately, while Jan3 CEO Samson Mow has recommended that all Coldcard users migrate to newly generated wallets regardless of firmware version as a precaution.
The consensus among security experts is that acting quickly remains the safest course of action.
What this means for self-custody
Importantly, researchers emphasize that this incident should not be interpreted as evidence that self-custody itself is fundamentally unsafe.
Instead, it highlights a different category of risk centered around firmware integrity, seed generation, and operational security, rather than the exchange-related risks often associated with centralized platforms.
According to Blockaid, most cryptocurrency losses during the first half of 2026 were linked to compromised private keys and operational security failures instead of smart contract vulnerabilities, placing the Coldcard incident within a broader industry trend.
Key lessons for hardware wallet users
The ongoing Coldcard incident reinforces several important security principles.
Hardware wallet protection depends not only on keeping devices offline but also on trustworthy firmware, secure seed generation, and responding quickly whenever verified vulnerabilities are discovered.
Security experts continue to recommend maintaining diversified storage strategies, verifying wallet creation procedures, and migrating assets promptly if a security issue is identified.
The Coldcard firmware vulnerability has now resulted in estimated losses exceeding $116 million, making it one of the most significant Bitcoin hardware wallet security incidents on record.
As investigations continue and mitigation efforts expand, the case highlights an important reality for the entire crypto industry: strong security requires constant vigilance. Protecting digital assets depends not only on choosing trusted hardware but also on maintaining updated software, secure operational practices, and responding rapidly whenever credible security risks emerge.
#Coldcard
@Gate_Square
@Gate Launch
Coldcard wallet attack surpasses $116 million as firmware vulnerability continues to impact users
A major security incident continues to unfold across the Bitcoin ecosystem as the ongoing Coldcard hardware wallet attack grows in scale. What initially appeared to be a targeted exploit has developed into one of the largest self-custody security events in Bitcoin's history, with on-chain investigations showing losses continuing to increase through early August.
The incident serves as a powerful reminder that even trusted security products require continuous monitoring, timely updates, and strong operational security practices.
How the vulnerability was exploited
According to research from Galaxy Research, the attack is linked to a firmware vulnerability affecting certain Coldcard devices dating back to March 2021.
The flaw weakened the randomness used during seed phrase generation. Since a wallet's seed phrase is responsible for creating its private keys, reduced randomness makes those keys significantly easier to predict. An attacker can potentially reconstruct affected wallets offline without needing physical access to the device itself.
The first attack wave demonstrated how serious the issue had become, compromising 1,196 wallet addresses within just 41 minutes and draining approximately 1,082 BTC, valued at around $70 million at that time.
Losses continue to rise
Subsequent attack waves expanded the damage considerably.
By August 3, estimated losses had climbed to approximately 1,367 BTC, worth nearly $89 million. Later estimates reported by Forbes placed total losses at more than $116 million, with over 5,200 wallet addresses believed to have been affected.
One widely reported incident involved a single user losing approximately C$1.6 million, despite following commonly recommended hardware wallet security practices.
Galaxy Research has also reported roughly 600 blockchain addresses believed to be associated with the attackers to federal investigators and cybersecurity organizations to support the ongoing investigation.
Manufacturers respond with security updates
The vulnerability has also been confirmed by Block's Bitcoin Engineering and Security team, which attributed the issue to a coding error affecting specific firmware versions.
In response, Coinkite has released updated firmware designed to prevent newly created wallets from being affected going forward. Company CEO Rodolfo Novak has encouraged users to transfer their assets immediately, while Jan3 CEO Samson Mow has recommended that all Coldcard users migrate to newly generated wallets regardless of firmware version as a precaution.
The consensus among security experts is that acting quickly remains the safest course of action.
What this means for self-custody
Importantly, researchers emphasize that this incident should not be interpreted as evidence that self-custody itself is fundamentally unsafe.
Instead, it highlights a different category of risk centered around firmware integrity, seed generation, and operational security, rather than the exchange-related risks often associated with centralized platforms.
According to Blockaid, most cryptocurrency losses during the first half of 2026 were linked to compromised private keys and operational security failures instead of smart contract vulnerabilities, placing the Coldcard incident within a broader industry trend.
Key lessons for hardware wallet users
The ongoing Coldcard incident reinforces several important security principles.
Hardware wallet protection depends not only on keeping devices offline but also on trustworthy firmware, secure seed generation, and responding quickly whenever verified vulnerabilities are discovered.
Security experts continue to recommend maintaining diversified storage strategies, verifying wallet creation procedures, and migrating assets promptly if a security issue is identified.
The Coldcard firmware vulnerability has now resulted in estimated losses exceeding $116 million, making it one of the most significant Bitcoin hardware wallet security incidents on record.
As investigations continue and mitigation efforts expand, the case highlights an important reality for the entire crypto industry: strong security requires constant vigilance. Protecting digital assets depends not only on choosing trusted hardware but also on maintaining updated software, secure operational practices, and responding rapidly whenever credible security risks emerge.
#Coldcard
@Gate_Square
@Gate Launch






















